An esim implementation satellite card solution

By introducing a new satellite profile structure and encryption/decryption mechanism into eSIM, the software and encryption algorithm upgrade issues of cellular cards have been resolved, achieving the unification of cellular and satellite card functions, ensuring the security of satellite data and business support for multiple network operators.

CN116193423BActive Publication Date: 2026-05-05CHIPSET SECURITY WE THINGS (SHANGHAI)MICROELECTRONICS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHIPSET SECURITY WE THINGS (SHANGHAI)MICROELECTRONICS TECH CO LTD
Filing Date
2023-03-29
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing eSIM technology cannot support software upgrades and encryption algorithm upgrades for cellular cards, and the plaintext storage of cellular parameters and authentication keys poses security risks, failing to meet the business needs of multiple network operators.

Method used

A novel satellite profile structure and encryption/decryption structure are proposed, which divides the satellite into a satellite software area and a satellite data area, and synchronously configures the encryption/decryption mechanism in the mode configuration area to achieve encrypted processing of satellite software and data, supporting satellite communication.

Benefits of technology

It unifies the functions of cellular and satellite cards, ensures the security of satellite data, supports the business needs of multiple network operators, and enables remote download and management of satellite software and data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116193423B_ABST
    Figure CN116193423B_ABST
Patent Text Reader

Abstract

This application relates to a solution for implementing a satellite card using eSIM, thereby enabling satellite card functionality. It also allows for a single SIM card to support both cellular and satellite signals. The new satellite profile structure and data encryption method, utilizing the profile format and encryption method provided in this application, allows satellite software and data to be downloaded to the SIM card, achieving remote download and management of satellite SIM card software and data. Since this solution supports both cellular and satellite numbers, it retains the original profile's cellular configuration area and adds a new configuration area for the satellite software and data described herein. This means that cellular and satellite numbers are configured in a unified profile and downloaded to the SIM card. This allows the SIM card to support both cellular and satellite number functions with a single profile download.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of satellite communication technology, and in particular to a novel satellite profile structure, a satellite profile encryption / decryption structure, a SIM satellite card, and satellite communication methods and electronic devices thereof. Background Technology

[0002] eSIM: Embedded-SIM. The eSIM referred to in this article is the eSIM product technology defined by GSMA.

[0003] As shown in the attached instruction manual Figure 1 The diagram shown illustrates the mechanism and principle of eSIM.

[0004] The principle of eSIM is that certain basic functions are implemented in the SIM card. All cellular network access data is carried in profile format and downloaded to the SIM card through a number management platform. The SIM card parses and stores all data in the profile, realizing a complete cellular card function.

[0005] This technology allows cellular numbers to be downloaded from the platform to an empty eSIM card. It also supports multiple cellular cards. However, currently only one cellular card can be in use at a time.

[0006] This is because the data storage format, authentication methods, etc., defined by GSMA are only applicable to network parameters of already commonly used cellular standards.

[0007] This method cannot support the addition of new network algorithms, encryption algorithms, or new data storage formats; moreover, the cellular parameters and authentication keys stored in the profile are in plaintext and can only be encrypted on the download platform, which cannot meet the needs of the current business scenario. Specifically:

[0008] As attached Figure 2 The image shows the cellular profile format. In the current eSIM mechanism, only various data related to cellular network access are encapsulated in the cellular profile and downloaded to the SIM card. The content transmitted through the profile is only cellular data and cannot support upgrades to cellular-related processing software, such as upgrades to cellular authentication algorithms or encryption algorithms.

[0009] This is because the cellular data stored in the profile is in plaintext, including the network access authentication key, PIN code, network parameters, etc. The plaintext data in the profile can only be encrypted on the number download platform. For virtual operators who possess number data but use third-party download platforms, in order to download numbers to the SIM card, they must provide the number and other parameters in plaintext to the third-party download platform. This poses a significant security risk due to the data being leaked by the third party. Summary of the Invention

[0010] To address the aforementioned issues, this application proposes a novel satellite profile structure, a satellite profile encryption / decryption structure, a SIM satellite card, a satellite communication method thereof, and an electronic device thereof.

[0011] This application proposes a novel satellite profile structure, including a mode configuration area encapsulated within the satellite profile, wherein the mode configuration area includes:

[0012] The satellite software area is used to store satellite software.

[0013] The satellite data area is used to store satellite parameters;

[0014] The satellite software area and the satellite data area are partitioned within the mode configuration area.

[0015] As an optional implementation of this application, preferably, the satellite software stored in the satellite software area is executable binary code converted from compiled code.

[0016] As an optional implementation of this application, preferably, the satellite software area includes the following functional modules:

[0017] Satellite network access parameter storage module, satellite authentication module, and security algorithm module.

[0018] As an optional implementation of this application, preferably, the satellite parameters stored in the satellite data area include:

[0019] Card number, constellation parameters, network access authentication key, and encryption / decryption key.

[0020] As an optional implementation of this application, preferably, the satellite parameters stored in the satellite data area are stored in plaintext form.

[0021] In another aspect, this application proposes a satellite profile encryption / decryption structure, including:

[0022] The aforementioned new satellite profile structure;

[0023] The new satellite profile structure is equipped with encryption and decryption mechanisms when encapsulating the mode configuration area.

[0024] As an optional implementation of this application, preferably, the encryption / decryption mechanism performs encryption / decryption tasks based on the satellite data decryption module and the parameters used for data decryption.

[0025] As an optional implementation of this application, preferably, the satellite data decryption module is deployed in the satellite software area, and the parameters used for data decryption are stored in the satellite data area.

[0026] In another aspect, this application also proposes a SIM satellite card, which adopts the profile format of the new satellite profile structure and writes satellite software and satellite data.

[0027] In another aspect, this application also proposes a SIM satellite card, which adopts the profile format of the satellite profile encryption and decryption structure and writes satellite software containing decryption software and decrypted satellite data.

[0028] In another aspect, this application also proposes a satellite communication method based on the SIM satellite card.

[0029] In another aspect, this application also proposes an electronic device comprising:

[0030] processor;

[0031] Memory used to store processor-executable instructions;

[0032] The processor is configured to implement the satellite communication method when executing the executable instructions.

[0033] Technical effects of the present invention:

[0034] This application utilizes the eSIM mechanism to implement satellite card functionality. It also enables a single SIM card for both cellular and satellite data. The new satellite profile structure and data encryption method allow satellite software and data to be downloaded to the SIM card using the profile format and encryption method provided in this application, achieving remote download and management of satellite SIM card software and data. Since this solution supports both cellular and satellite numbers, the original profile's cellular configuration area is retained, and a new configuration area for the satellite software and data described herein is added. This means that cellular and satellite numbers are configured in a unified profile and downloaded to the SIM card. This allows the SIM card to support both cellular and satellite number functions with a single profile download.

[0035] Other features and aspects of this disclosure will become clear from the following detailed description of exemplary embodiments with reference to the accompanying drawings. Attached Figure Description

[0036] The accompanying drawings, which are included in and form part of this specification, illustrate exemplary embodiments, features, and aspects of this disclosure together with the specification and serve to explain the principles of this disclosure.

[0037] Figure 1 The diagram illustrates the mechanism of eSIM.

[0038] Figure 2 The diagram is shown in cellular profile format.

[0039] Figure 3 The diagram shown is a structural schematic of the new satellite profile structure of the present invention;

[0040] Figure 4 The diagram shown is a schematic representation of the satellite profile encryption / decryption structure of this invention.

[0041] Figure 5 The diagram shows the encryption and decryption mechanism of the satellite profile encryption and decryption structure of this invention.

[0042] Figure 6 The flowchart shown is one of the encryption methods of the present invention;

[0043] Figure 7 The flowchart shown is one embodiment of satellite data encryption according to the present invention;

[0044] Figure 8 The diagram illustrates a three-level key processing flow according to the present invention.

[0045] Figure 9 The diagram shows a processing flow diagram of a 16-byte fixed value according to the present invention;

[0046] Figure 10 The diagram shows a structural schematic of the profile data assembly format of the present invention.

[0047] Figure 11 The diagram shown is a schematic representation of the application system of the electronic device of the present invention. Detailed Implementation

[0048] Various exemplary embodiments, features, and aspects of this disclosure will now be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of the embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.

[0049] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments.

[0050] Furthermore, to better illustrate this disclosure, numerous specific details are set forth in the following detailed description. Those skilled in the art will understand that this disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art have not been described in detail in order to highlight the main points of this disclosure.

[0051] In the description of this embodiment, the satellite encapsulation and application interactions of various functional modules are not considered in this application. This embodiment only upgrades the hardware structure and functions. For example, the specific security algorithm used in the security algorithm module is not within the scope of this embodiment.

[0052] Example 1

[0053] like Figure 3 As shown, this embodiment designs a new satellite profile structure and data encryption method. The software and data required for satellite network access are encapsulated together in the profile and downloaded to the eSIM card.

[0054] This application proposes a novel satellite profile structure, including a mode configuration area encapsulated within the satellite profile, wherein the mode configuration area includes:

[0055] The satellite software area is used to store satellite software.

[0056] The satellite data area is used to store satellite parameters;

[0057] The satellite software area and the satellite data area are partitioned within the mode configuration area.

[0058] As an optional implementation of this application, preferably, the satellite software stored in the satellite software area is executable binary code converted from compiled code.

[0059] As an optional implementation of this application, preferably, the satellite software area includes the following functional modules:

[0060] Satellite network access parameter storage module, satellite authentication module, and security algorithm module.

[0061] As an optional implementation of this application, preferably, the satellite parameters stored in the satellite data area include:

[0062] Card number, constellation parameters, network access authentication key, and encryption / decryption key.

[0063] As an optional implementation of this application, preferably, the satellite parameters stored in the satellite data area are stored in plaintext form.

[0064] In this embodiment, the eSIM mechanism is used to implement satellite card functionality. Furthermore, it can also realize cellular and satellite SIM card functionality.

[0065] In the aforementioned new satellite profile structure, this application encapsulates the satellite's required software, data, keys, etc., into a mode configuration area. This mode configuration area is further divided into a satellite software area and a satellite parameter area. The satellite software area stores the satellite card's software, which is executable binary code compiled from existing code. This code includes functions such as satellite network access parameter storage, satellite authentication, and security algorithms.

[0066] The satellite parameter area contains satellite-related parameters, including card number, constellation parameters, network access authentication key, encryption and decryption key, etc.

[0067] Satellite software and data are located in the mode configuration area of ​​the profile and are downloaded to the SIM card in one go. The SIM card uses the satellite codes and parameters in the profile to implement various related functions of the satellite card.

[0068] The SIM card can use the satellite code and parameters in the profile of this embodiment to realize various related functions of the satellite card. The method of using the SIM card as a satellite concentric card for satellite communication can refer to existing satellite communication schemes, and will not be described in detail in this embodiment.

[0069] Example 2

[0070] This embodiment adds satellite encryption functionality to the satellite profile structure of Embodiment 1 above, thereby increasing the encryption processing of data.

[0071] Because satellite parameters are stored in plaintext, this method is suitable when the satellite profile management is handled by the satellite operating company. However, it is suitable when there are other business operation models, such as when profile management needs to be delegated to a third-party company, but the satellite authentication key needs to be kept confidential from the third-party company.

[0072] The scheme in Embodiment 1 above can be further upgraded by adding encryption processing for the data.

[0073] like Figure 4 As shown, in another aspect, this application proposes a satellite profile encryption / decryption structure, including:

[0074] The above-described new satellite profile structure; see the structural description in Example 1 for details;

[0075] The new satellite profile structure is equipped with encryption and decryption mechanisms when encapsulating the mode configuration area.

[0076] As an optional implementation of this application, preferably, the encryption / decryption mechanism performs encryption / decryption tasks based on the satellite data decryption module and the parameters used for data decryption.

[0077] As an optional implementation of this application, preferably, the satellite data decryption module is deployed in the satellite software area, and the parameters used for data decryption are stored in the satellite data area.

[0078] like Figure 4 As shown, a satellite data decryption function is added to the satellite software, and parameters for data decryption are added to the satellite data. The satellite data is encrypted using a key and then placed in the satellite parameter area. That is, the satellite parameter area stores both encrypted satellite parameters and data decryption parameters.

[0079] like Figure 5 As shown, the encryption and decryption mechanism for satellite parameters implements the following usage logic:

[0080] The satellite data owner transmits the satellite software, encrypted satellite data, and decryption parameters to a third-party platform. The third-party platform packages these three data items into a profile format defined in this document and then passes it to the SIM card. The SIM card uses the decryption parameters and the decryption software within the satellite software to decrypt the encrypted satellite data. The SIM card then saves the satellite software and decrypted satellite data to its storage area, enabling normal use thereafter.

[0081] Encryption and decryption mechanisms are required. Satellite data owners need to encrypt satellite data. There are various encryption methods. This embodiment provides one encryption and decryption method for reference.

[0082] like Figure 6 As shown, the master key undergoes a first-level distribution to obtain a first-level key, which is used solely for satellite parameter encryption. The master key is set to a 16-byte AES key. The first-level distribution parameter consists of the key purpose string (e.g., the ASCII code of encptData), a key sequence number (e.g., 0x0001, which can be replaced with 0x0002, etc., typically one sequence number per batch), and the year and month (0x231), forming a 16-byte distribution parameter. This distribution parameter is then encrypted with AES using the master key, resulting in a 16-byte number, which serves as the first-level key.

[0083] like Figure 7The diagram illustrates the three-level key processing method. The second-level key is obtained by processing the first-level key and the second-level distribution parameter. The second-level distribution parameter can have several options; for example, it can use the satellite card's unique identifier (e.g., 10 bytes) plus the satellite data encryption algorithm version number (0x010, where 0x01 represents the major version number and 0x0 represents the minor version number) plus the year and month (0x231) to form a 16-byte second-level distribution parameter. The second-level distribution parameter is then encrypted using AES with the first-level key, resulting in a 16-byte value, which serves as the second-level key.

[0084] The second-level key and the third-level distribution parameter are used to obtain the third-level key. There are several options for the third-level distribution parameter; for example, a 16-byte random number can be generated. The third-level distribution parameter is then encrypted using AES with the second-level key, resulting in a 16-byte third-level key. This third-level key is used to encrypt the satellite data.

[0085] like Figure 8 The diagram illustrates the three-level key processing procedure. A fixed 16-byte value is required, which is used in the calculation and securely stored in the satellite software. The first step involves encrypting the satellite plaintext data using the 16-byte fixed value. This can be achieved by XORing the satellite data in 16-byte segments using the fixed value, or by using the 16-byte fixed value as the AES key to encrypt the satellite data. This yields the satellite parameters after the first-level processing. The MAC address is then calculated using the third-level key on the first-level processed satellite parameters, which can be done using the AES MAC calculation method. Finally, the MAC address is added to the first-level processed satellite parameters, and the encrypted satellite parameters are obtained using the third-level key.

[0086] By processing the level 3 key with a fixed 16-byte value, XOR or AES encryption can be used to obtain the encrypted level 3 key.

[0087] like Figure 9 The diagram illustrates how the 16-byte fixed value is handled. This 16-byte fixed value is securely stored in the satellite software. Security measures include segmenting the fixed value for storage and encrypting changes during storage.

[0088] The AES encryption method mentioned above can have multiple modes, such as AES CBC. For data that is less than a multiple of 16 bytes, padding is required first. Padding can be done in various ways, such as first padding with a byte of 0x80, then padding the remaining bytes with 0x00. Then, AES CBC calculation is performed.

[0089] After the above encryption steps, the binary code obtained after compiling the satellite code and the encrypted satellite parameters can be handed over to a third party to assemble the profile, obtain the data assembly format, and send it to the satellite card. There is no need to worry about the satellite data being leaked from third-party channels.

[0090] Data assembly format such as Figure 10 As shown. Using the profile format and data encryption method described in this article, satellite software and data are distributed to the SIM card. The SIM card then performs the reverse operation to decrypt the data and store and manage the software and data.

[0091] The above method can be used to remotely download and manage satellite SIM card software and data.

[0092] Furthermore, if it is desired to support both cellular and satellite numbers simultaneously, the original profile's cellular configuration area is retained, and a new configuration area for satellite software and data, as described in this article, is added. This means configuring both cellular and satellite numbers in a single profile and downloading it to the SIM card. This allows the SIM card to support both cellular and satellite numbering functions with a single profile download.

[0093] It should be noted that although the above encryption and decryption are illustrated using a three-level key as an example, those skilled in the art will understand that this disclosure is not limited to this. In fact, users can flexibly set the key level according to their actual application scenarios, as long as the technical functions of this application can be achieved by following the above technical methods.

[0094] Obviously, those skilled in the art should understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the control methods described above. Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the control methods described above. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium can also include combinations of the above types of memory.

[0095] Example 3

[0096] Based on the implementation principle of Embodiment 2, this application also proposes a SIM satellite card, wherein the SIM satellite card adopts the profile format of the new satellite profile structure and writes satellite software and satellite data.

[0097] For details on the data written to the SIM satellite card, please refer to the description in Example 1.

[0098] Example 4

[0099] In another aspect, this application also proposes a SIM satellite card, which adopts the profile format of the satellite profile encryption and decryption structure and writes satellite software containing decryption software and decrypted satellite data.

[0100] For details on the data written to the SIM satellite card, please refer to the description in Example 2.

[0101] Example 5

[0102] In another aspect, this application also proposes a satellite communication method based on the aforementioned SIM satellite card. The satellite communication method can be implemented by referring to existing satellite communication schemes.

[0103] Example 6

[0104] like Figure 11 As shown, further, this application also proposes an electronic device for implementing a satellite card via eSIM, comprising:

[0105] processor;

[0106] Memory used to store processor-executable instructions;

[0107] The processor is configured to implement the eSIM satellite card implementation scheme method when executing the executable instructions.

[0108] This disclosure discloses an electronic device including a processor and a memory for storing processor-executable instructions. The processor is configured to implement any of the eSIM-based satellite card implementation schemes described above when executing the executable instructions.

[0109] It should be noted here that the number of processors can be one or more. Furthermore, the electronic device in this embodiment may also include input devices and output devices. The processor, memory, input devices, and output devices can be connected via a bus or other means, without specific limitations herein.

[0110] As a computer-readable storage medium, the memory can be used to store software programs, computer-executable programs, and various modules, such as the program or module corresponding to the eSIM satellite card implementation scheme of this disclosure. The processor executes various functional applications and data processing of the electronic device by running the software program or module stored in the memory.

[0111] Input devices can be used to receive input digital numbers or signals. These signals can be key signals related to user settings and function control of the device / terminal / server. Output devices can include display devices such as screens.

[0112] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, and are not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical applications, or technical improvements to the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A method for encapsulating a satellite profile structure, characterized in that, The satellite profile includes a mode configuration area, which comprises: The satellite software area is used to store satellite software, and the satellite software area includes the following functional modules: satellite network access parameter storage module, satellite authentication module, and security algorithm module; The satellite data area is used to store satellite parameters, which include: card number, constellation parameters, network access authentication key and encryption / decryption key. The satellite software area and the satellite data area are partitioned within the mode configuration area.

2. The satellite profile structure encapsulation method according to claim 1, characterized in that, The satellite software stored in the satellite software area is executable binary code converted from compiled code.

3. The satellite profile structure encapsulation method according to claim 1, characterized in that, The satellite parameters stored in the satellite data area are stored in plaintext.

4. The satellite profile structure encapsulation method according to claim 1, characterized in that, include: The satellite profile remote download management system is equipped with an encryption / decryption mechanism when encapsulating the mode configuration area.

5. The satellite profile structure encapsulation method according to claim 4, characterized in that, When the encryption / decryption mechanism performs encryption / decryption tasks, it does so based on the satellite data decryption module and the parameters used for data decryption.

6. The satellite profile structure encapsulation method according to claim 5, characterized in that, The satellite data decryption module is deployed in the satellite software area, and the parameters used for data decryption are stored in the satellite data area.

7. A remote download management method for a SIM satellite card, characterized in that, The method employs the profile format of the satellite profile structure encapsulation method described in any one of claims 1-3, and writes satellite software and satellite data.

8. A remote download management method for a SIM satellite card, characterized in that, The method employs the profile format of the satellite profile structure encapsulation method described in any one of claims 4-6, and writes satellite software containing decryption software and decrypted satellite data.

Citation Information

Patent Citations

  • Anti-switching method and anti-switching system based on Internet-of-things SIM card

    CN107318103A

  • Session management function derived core network assisted radio access network parameters

    CN113678510A